Hybrid Cloud Messaging Framework for Secure On-Premise Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Hybrid cloud environments face challenges in establishing secure, bi-directional communication between cloud and on-premise services, particularly due to differences in programming models and security concerns, which hinder seamless integration and communication between applications developed by different developers.
Innovation Solution
A method and computer program product that receive a hybrid cloud application package, deployable in both cloud and on-premise environments, establish a secure bi-directional communication tunnel, and utilize a messaging framework to enable communication between cloud and on-premise applications, masking network connection information and facilitating communication between cloud and on-premise services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a hybrid cloud environment allows workload execution to move between private and public clouds, then flexibility and data deployment options are improved, but secure bi-directional communication between cloud and on-premise services becomes more difficult to establish
Solution Approach 1:
The patent introduces a messaging framework as an intermediary layer that enables secure bi-directional communication between cloud and on-premise services. This framework includes a message broker that routes messages through secure channels, masking network connection information and providing authentication mechanisms, thereby resolving the communication security challenge while maintaining workload flexibility
2Ease of operation
If cloud and on-premise services communicate seamlessly, then application integration is improved, but differences in programming models create complexity in establishing secure communication
Solution Approach 1:
The patent segments the communication system into distinct components: a messaging framework layer, a message broker, and service interfaces. This segmentation isolates the complexity of programming model differences to specific layers while providing standardized interfaces for cloud and on-premise services, enabling seamless communication without requiring both sides to understand each other's internal models
Solution Approach 2:
The messaging framework acts as an intermediary that translates between different programming models. It provides standardized message formats and protocols that bridge the gap between cloud-native and on-premise applications, allowing them to communicate seamlessly despite their different architectural backgrounds
3Ease of operation
If network connection information is exposed for communication between cloud and on-premise environments, then connectivity is improved, but security risks increase
Solution Approach 1:
The messaging framework serves as an intermediary that masks network connection information. Instead of exposing direct network endpoints, it provides abstracted message routing through the framework, which handles authentication and encryption internally, thereby maintaining connectivity while hiding sensitive network details from both cloud and on-premise services
Data Source
AI summary
As disclosed herein a method, executed by a computer, for enabling a hybrid cloud environment includes receiving, on a cloud environment, a hybrid cloud application package comprising a deployable cloud package and a deployable on-premise package, and deploying the deployable cloud package in a container on the cloud environment, providing a cloud application. The method further includes establishing a secure bi-directional communication tunnel between the cloud environment and an on-premise environment, thereby masking network connection information, and sending, with the secure bi-directional messaging framework, the deployable on-premise package to an on-premise server in the on-premise environment. The method further includes sending a message, with the secure bi-directional messaging framework, requesting services from an on-premise application, and receiving a response from the on-premise application. A computer program product corresponding to the above method is also disclosed herein.


